hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

DumpZ
I was wondering if it's possible to hide system services. Because on my test server/honeypot i saw some processes running which returned every time after boot. I searched the registry i really could find allot. (i'm not really familliar in the registry so maybe that is the problem)

But if it's possible to hide system services is there also a way to unhide it?
Flowers
Try this http://hxdef.czweb.org/ (rootkit)
(if hide, it s hard to unhide tongue.gif)
DumpZ
Well thanks but im kinda looking for something to unhide it aswell.
tuby
If you're hxdef.ini is good, with a adequat root process, you can uninstall hxdef easily.

For example if in [root process] , u have backcmd.exe (copy of cmd.exe) :

backcmd /c hxdef -:uninstall

After a reboot, you can see/modify/delete your services.

Enjoy'

LKM
As the guy before me said, HXDEF has a wide range of interesting use in order to hide / unhide services, process, tasks

I recommend you to try it, and then post here if you've got problems with it.

The only downside is that it made some hidden progs to crash on remote computers :|
phrozen77
you may want to try rkd (rootkit detector) from haxorcitos...

-> google
radien
Yup, I can remember sometime, that one of my friends keep track of processes(keyloggers/trojans/virii) that hide behind svchost.exe. It's because svchost runs some of windows services somehow. So look for svchost and how to hide behind it.

I hope it helps, smile.gif
DumpZ
Thanks you guys i'm getting started right away
Synchr0
thx its nice rootkit:D ph34r.gif
Lyeses

Hxdef is a good rootkit.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.